Opens in a new tab
vmblog logo 2024 wht (updated)

Safer Internet Day 2026: Security Leaders on AI Agents, Data Resilience, and Zero Trust

Share: 

David Marshall | Published: February 10, 2026
vmblog safer internet day 2026

As artificial intelligence continues to reshape how organizations operate, this year’s Safer Internet Day arrives at a critical inflection point. Security and identity leaders are sounding the alarm on a fundamental shift in the threat landscape: AI agents are no longer passive tools, but autonomous actors operating at machine speed across digital ecosystems. From identity verification and risk assessment to data protection and cyber resilience, industry experts are unified in one message-a safer internet requires moving beyond assumptions of trust to a framework of continuous, verified authentication. This year’s commentary from enterprise security leaders reveals that protecting users, data, and organizational integrity in an increasingly agentic digital world demands a fundamental rethinking of how we approach identity, access control, and resilience.

The conversation around internet safety has evolved significantly as AI adoption accelerates. While the technology itself isn’t inherently dangerous, it has dramatically lowered the barriers to scaling malicious behavior-from sophisticated scams and identity impersonation to data breaches and ransomware attacks. Security leaders emphasize that a safer internet begins with awareness and preparation, not just detection. Their message is clear: organizations and individuals must implement Zero Trust principles across all levels, invest in immutable data protection and tested recovery capabilities, and adopt identity-first security models that verify not just who is accessing systems, but what is accessing them, under what context, and with what intent. The consensus among industry experts is that internet safety is a shared responsibility requiring continuous vigilance, ongoing testing, and adaptive security practices.

++

Anthony Cusimano, solutions director at Object First

As AI becomes part of how we work, shop, and play, it’s important to remember that these tools are only as good as the data behind them. If that data isn’t protected, backed up, and kept safe from cyber threats, even the smartest technology can fail. A safer internet isn’t just about stopping hackers, it’s about being prepared, protecting information, and making sure data can always be recovered. When organizations focus on keeping data secure and resilient, everyone benefits from a more reliable online world. 
  
However, just having these backups isn’t enough. Many organizations think they’re protected because they have backups, but true cyber resilience and internet safety means knowing those backups actually work. As cyber threats continue to evolve, keeping the internet safer requires ongoing effort: regularly testing recovery plans, protecting data from being altered or locked, and making sure important information can always be restored. When businesses invest continuously in resilience, it helps create a more secure and reliable online experience for everyone. 
  
While companies adopt immutable storage to improve security, meet regulatory standards, and build trust with stakeholders, individuals should apply the same approach to their personal data by choosing secure, tamper-proof backups. A safer internet starts with a Zero Trust approach at all levels, ensuring that security is based on verification and resilience rather than trust. 

++

Alex Laurie, Go-To-Market Chief Technology Officer (GTM CTO) at Ping Identity

The conversation this Safer Internet Day must evolve to reflect a new reality: AI agents are no longer just tools, they’re autonomous actors operating at machine speed across the digital ecosystem. While AI agents unlock powerful efficiencies, they also introduce new security risks by acting like users, making decisions, and accessing systems in ways that are difficult to distinguish from human behavior. When left ungoverned, these agents can be exploited or behave unpredictably, expanding the attack surface and undermining what can be trusted.

Combating this risk requires a shift toward verified trust, where every digital interaction is continuously validated, not assumed. Organizations must move beyond static credentials and adopt identity-first security models that verify who, and what, is accessing systems, under what context, and with what intent. By combining strong identity verification, real-time risk assessment, and adaptive access controls, businesses can enable AI innovation while protecting users, data, and trust in an increasingly agentic internet.

++

Mark Wojtasiak, SVP of Product Research and Strategy, Vectra AI

AI didn’t make the internet unsafe, it made unsafe behavior easier to scale. A safer internet starts with awareness. 

AI has lowered the barrier for scams, impersonation, and abuse – not because AI is evil, but because of what it enables. Making the internet safer starts with awareness: teaching people how to question what looks legitimate, protect their identities, and understand that trust online must be earned, not assumed.

++

Henrique Teixeira, SVP, Saviynt

On Safer Internet Day, can you trust AI with your email password? OpenClaw (aka Moltbot, Clawdbot) has hit the top of the charts in popularity given how easy and democratized access to AI has become. Users, however, should proceed with caution. Even when properly configured, it still poses significant identity security risks. If I had to simplify how OpenClaw credentials work, it’s basically this: if you want your bot to do useful stuff, you need to provide it with  credentials (usernames and passwords, cryptographic keys, etc.) with high levels of permission. For example, if you want OpenClaw to streamline your Gmail inbox, you need to give it full access to your email account and how most people will handle that poses a huge risk of credential exposure.

Best case, users follow steps like this, which use an OAuth consent flow instead of hard-coding an email and password. That’s better, but it still involves generating JSON files and light coding, and the app is still flagged as “unsafe” by Google because’ it hasn’t been verified. Assuming that OpenClaw is ‘my app’ accessing ‘my inbox’ and that this is sufficient security vetting glosses over how most modern breaches happen: attackers abuse existing credentials, then move laterally and escalate privileges. OAuth tokens are not immune from being stolen or reused, and the bot itself could be poisoned to reveal more about the permissions it carries. Most people worry about AI privacy and trust risks, but the real risk here is identity. Stay safe! 

++

Graeme Bunton, Executive Director of the NetBeacon Institute

As we reflect on Safer Internet Day, the growing sophistication of malicious actors should be concerning to all. Responding to these threats requires everyone, and especially the Internet infrastructure community, to work together to both protect resources and networks, and also to disrupt malicious activity. 

Effective reporting, tracking, and disruption of harms like phishing is incredibly difficult, making coordinated action harder than it should be. That is why collaboration among registries, registrars, web hosts, cloud service providers, researchers, and security organizations is critical to building shared tools, establishing best practices, and sharing data. 

Real progress happens when tools are accessible, standards are clear, and we have the resources to act. The easier we make it to do the right thing, the stronger and safer the Internet becomes for all.

##